Defender for Cloud - Container Security - What's New in the Last 6 Months
Defender for Cloud receives container-related changes throughout its regular release cycle. Looking back from January through July 2026, those updates cover posture management, vulnerability assessment, runtime protection, enforcement, sensor maintenance, private connectivity, and advanced hunting across Azure, AWS, and GCP.
The list is lifecycle-deduplicated: when a capability moved from preview to general availability during this period, only its latest GA state is shown. Preview entries remain where no later GA announcement exists.
Container Updates from January to July 2026
The table covers AKS, EKS, GKE, Azure Arc-enabled Kubernetes, private clusters, serverless containers, image scanning, runtime protection, Defender sensor releases, and container-relevant advanced hunting tables.
Each feature name links to the most specific Microsoft Learn page available.
| Month | Status | Scope | Feature or update | What changed |
|---|---|---|---|---|
| 2026-07 | π’ GA | Kubernetes | Container-level misconfiguration recommendations | Agentless KSPM evaluates individual containers; older cluster-level recommendations are deprecated. |
| 2026-07 | π’ GA | AKS | Upgrade AKS Version recommendation | Identifies the minimum upgrade required for vulnerable managed system pods. |
| 2026-07 | π’ GA | EKS, GKE | Runtime-discovered image vulnerability assessment | Extends scanning beyond registry images to images found in running workloads. |
| 2026-07 | π’ GA | EKS, GKE | Kubernetes node vulnerability assessment | Adds OS-level node vulnerability assessment equivalent to existing AKS coverage. |
| 2026-07 | π’ GA | Container images | Docker Hardened image scanning | Adds Defender Vulnerability Management coverage for Docker Hardened images. |
| 2026-07 | π’ GA | AKS, Arc, AWS, GCP | Kubernetes misconfiguration enforcement | Adds admission-time audit and blocking through automatic provisioning or Helm. |
| 2026-07 | π’ GA | ACA, ACI, ECS Fargate | Serverless-container discovery and posture | Adds inventory, misconfiguration and vulnerability findings, and attack-path analysis. |
| 2026-07 | π’ GA | Helm, Arc for Kubernetes | Defender sensor v0.11 release line | Became GA in July 2026 and is supported through July 2027. |
| 2026-06 | π’ GA | AWS, GCP | Expanded multicloud posture coverage | Adds approximately 90 resource types and 200+ recommendations, including containers. |
| 2026-06 | π΅ Update | Kubernetes, registries | Expanded container support for cloud scopes | Adds K8s namespace, K8s cluster, multicloud registry, and repository scopes. |
| 2026-06 | π‘ Preview | AWS, GCP | 60+ multicloud recommendations | Adds recommendations spanning containers and other resource categories. |
| 2026-06 | π‘ Preview | Private EKS, GKE clusters | Defender sensor v0.11.3 | Adds Defender sensor support for private EKS and GKE clusters. |
| 2026-06 | π’ GA | Multicloud audit activity | CloudAuditEvents advanced hunting table | Exposes cloud audit activity for control-plane and container investigations. |
| 2026-06 | π’ GA | Cloud and container DNS | CloudDnsEvents advanced hunting table | Exposes DNS activity from cloud infrastructure environments. |
| 2026-06 | π’ GA | Multicloud workloads | CloudProcessEvents advanced hunting table | Exposes process activity from multicloud hosted workloads. |
| 2026-05 | π‘ Preview | Private Kubernetes clusters | Private-cluster sensor protection | Adds gated deployment, binary-drift detection, and malware detection support. |
| 2026-05 | π‘ Preview | EKS, GKE | Kubernetes-node malware detection | Extends node malware coverage beyond AKS. |
| 2026-05 | π’ GA | AKS, EKS, GKE | Direct Helm sensor deployment | Replaces installation scripts with environment-specific Helm commands. |
| 2026-05 | π’ GA | Containers, container images | Individual vulnerability recommendations | Replaces legacy grouped container and image recommendations. |
| 2026-05 | π’ GA | Helm, Arc, AKS | Sensor v0.10.5, v0.9.58 and v0.8.51 | Adds Nexus Baremetal compatibility plus dependency security and stability updates. |
| 2026-04 | π’ GA | EKS | Bottlerocket runtime protection | Adds runtime protection for EKS clusters using Bottlerocket. |
| 2026-04 | π’ GA | AKS, EKS, GKE | Runtime anti-malware detection and blocking | Adds configurable alerting and blocking policies for malicious runtime executables. |
| 2026-04 | π’ GA | AKS, EKS, GKE | DNS Detection for Kubernetes | Detects malicious domains and DNS tunnelling through the Helm-deployed sensor. |
| 2026-04 | π’ GA | Azure Government | Defender for Containers capabilities | Adds agentless discovery, attack paths, vulnerability assessment, compliance, and runtime protection. |
| 2026-04 | π’ GA | Helm, Arc for Kubernetes | Sensor v0.9 and v0.10 release lines | Both became stable in April 2026 and are supported through April 2027. |
| 2026-03 | π’ GA | AKS Automatic | Kubernetes gated deployment | Installs the sensor through Helm in kube-system, replacing the AKS add-on deployment. |
| 2026-03 | π‘ Preview | Container images, CI/CD | Code-to-runtime enrichment | Maps runtime recommendations through registries and pipelines back to source code. |
| 2026-03 | π‘ Preview | Kubernetes policy enforcement | CloudPolicyEnforcementEvents advanced hunting table | Exposes policy decisions and metadata for cloud security gating events. |
| 2026-03 | π’ GA / π‘ Preview | Defender sensor | Sensor security and platform updates | Adds Nexus compatibility, secret sanitisation, SELinux improvements, FIPS support, hardened images, and dependency fixes. |
| 2026-02 | π‘ Preview | Container workloads | Binary-drift blocking | Sensor v0.10.2 can block unauthorised runtime changes to container images. |
| 2026-02 | π’ GA | Container images | Minimus and Photon OS scanning | Extends image vulnerability scanning to both distributions. |
| 2026-02 | π’ GA / π‘ Preview | Defender sensor | Sensor performance improvements | Delivered through stable v0.8.47 and preview v0.9.50. |
| 2026-01 | π‘ Preview | Defender for Containers | Microsoft Security Private Link | Enables private connectivity between Defender for Cloud and protected workloads through private endpoints. |
Status key: π’ generally available, π‘ preview, and π΅ functional update. Mixed sensor rows combine changes shipped across stable and preview sensor branches in the same month.
What Stands Out
The first clear shift is multicloud parity. EKS and GKE now receive runtime image and node vulnerability assessment that was previously associated mainly with AKS. Malware detection is moving in the same direction, although EKS and GKE node coverage is still in preview.
The second is the move from observation towards enforcement. Kubernetes misconfiguration enforcement can audit or block resources at admission time, while binary-drift blocking and gated deployment add controls closer to workload execution. I would still start these controls in audit mode and review the impact before blocking production deployments.
The third is better investigation data in Defender XDR. CloudAuditEvents, CloudDnsEvents, and CloudProcessEvents are now GA, while CloudPolicyEnforcementEvents remains in preview. These tables matter for container investigations even though their names are broader than Kubernetes - they expose the audit, DNS, process, and policy activity around the workload.
The table is a release summary, not a support guarantee. Check the linked support matrix before enabling a capability because availability can differ by cloud, Kubernetes distribution, deployment method, and sensor version.
Sources
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
- https://learn.microsoft.com/en-us/defender-xdr/whats-new
Conclusion
Container security in Defender for Cloud changed quite a bit between January and July. The most useful improvements are not limited to another set of recommendations - Microsoft added private connectivity, more multicloud coverage, practical admission and runtime controls, serverless-container posture, and hunting tables that bring the resulting activity into Defender XDR.
The remaining previews are worth tracking, especially private-cluster protection, EKS and GKE malware detection, binary-drift blocking, and CloudPolicyEnforcementEvents. Those are the rows most likely to move again in the next release cycle.